Skip to main content
DockerCustomer feedback

A user discussing a Docker Desktop vulnerability on Mac notes they have switched to using OrbStack for their containerization needs.

What happened

Post: "CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes)"

Source

Comments on the post

4 of 13 comments
  • “> Deleting the file removes the volfs path. Holding it open keeps the nodeid. Together they leave the server with nothing but the string. Then the guest replaces the parent folder with a symlink. The server reads that string and sees a path that’s inside the mounted folder and allows it, but then the kernel reads the same string, follows the symlink, and opens a file on the host outside of the mou”

    u/ni5arga46 points · Sep 19, 2026View

  • “That's not what the word compromised means in this context, click bait”

    u/lcurole19 points · Sep 19, 2026View

  • “the actual bug is that the virtio-fs host server re-follows symlinks when it reopens a file it previously unlinked, so a guest can swap in a symlink and write outside the shared dir.”

    u/feng_sg3 points · Sep 21, 2026View

  • “I’m a bit new to docker on MAC. I’m using orbstack for userland docker contianers. I don’t think I’m affected: not using docker desktop or “sandboxes”.”

    u/Redditperegrino-7 points · Sep 19, 2026View

Extracted by Autobound

From the Signal API record
Signal
Customer feedback

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/netsec
Stage
Switched

Companies

  • OrbStackAlso named

The full record

From the Signal API record

Numbers

Mentions
6

Details

Timing
Completed
Category
General
Virality
High
Post kind
Link
Prominence
Aside
Company's role
Vendor

Topics and mentions

Topics

  • customer churn
  • containerization
  • macos

Flair

  • Contains AI

Products named

  • Docker Desktop

Extraction

Sentiment
Negative
Detected
Sep 19, 2026
signal_type
reddit-company
signal_subtype
customerFeedback

Use this data

Get every Reddit signal for Docker and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Docker this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/69bff1a3-31da-5fa7-a26b-3e53d3fba58c returns this record as JSON. POST /v1/companies/enrich returns every signal for docker.com.

{
  "signal_id": "69bff1a3-31da-5fa7-a26b-3e53d3fba58c",
  "signal_type": "reddit-company",
  "signal_subtype": "customerFeedback",
  "detected_at": "2026-09-19T06:25:58+00:00",
  "company": {
    "name": "Docker",
    "domain": "docker.com"
  },
  "data": {
    "nsfw": false,
    "stage": "switched",
    "awards": 0,
    "timing": "completed",
    "topics": [
      "customer churn",
      "containerization",
      "macos"
    ],
    "post_id": "1wkeh8n",
    "summary": "A user discussing a Docker Desktop vulnerability on Mac notes they have switched to using OrbStack for their containerization needs.",
    "category": "general",
    "comments": [
      {
        "url": "https://www.reddit.com/r/netsec/comments/1wkeh8n/comment/paq4e0r/",
        "depth": 0,
        "score": 46,
        "author": "ni5arga",
        "excerpt": "> Deleting the file removes the volfs path. Holding it open keeps the nodeid. Together they leave the server with nothing but the string. Then the guest replaces the parent folder with a symlink. The server reads that string and sees a path that’s inside the mounted folder and allows it, but then the kernel reads the same string, follows the symlink, and opens a file on the host outside of the mou",
        "posted_at": "2026-09-19T07:19:33.000Z",
        "author_url": "https://www.reddit.com/user/ni5arga/"
      },
      {
        "url": "https://www.reddit.com/r/netsec/comments/1wkeh8n/comment/paratbn/",
        "depth": 0,
        "score": 19,
        "author": "lcurole",
        "excerpt": "That's not what the word compromised means in this context, click bait",
        "posted_at": "2026-09-19T12:46:32.000Z",
        "author_url": "https://www.reddit.com/user/lcurole/"
      },
      {
        "url": "https://www.reddit.com/r/netsec/comments/1wkeh8n/comment/pb3hhau/",
        "depth": 0,
        "score": 3,
        "author": "feng_sg",
        "excerpt": "the actual bug is that the virtio-fs host server re-follows symlinks when it reopens a file it previously unlinked, so a guest can swap in a symlink and write outside the shared dir.",
        "posted_at": "2026-09-21T03:41:32.000Z",
        "author_url": "https://www.reddit.com/user/feng_sg/"
      },
      {
        "url": "https://www.reddit.com/r/netsec/comments/1wkeh8n/comment/paq1plu/",
        "depth": 0,
        "score": -7,
        "author": "Redditperegrino",
        "excerpt": "I’m a bit new to docker on MAC. I’m using orbstack for userland docker contianers. I don’t think I’m affected: not using docker desktop or “sandboxes”.",
        "posted_at": "2026-09-19T06:57:28.000Z",
        "author_url": "https://www.reddit.com/user/Redditperegrino/"
      }
    ],
    "evidence": [
      "[comment u/Redditperegrino] I’m a bit new to docker on MAC. I’m using orbstack for userland docker contianers. I don’t think I’m affected: not using docker desktop or “sandboxes”."
    ],
    "link_url": "https://www.accomplish.ai/blog/escaping-dockers-hypervisor/",
    "virality": "high",
    "post_date": "2026-09-19T06:25:58.000Z",
    "post_kind": "link",
    "sentiment": "negative",
    "subreddit": "netsec",
    "post_flair": [
      "Contains AI"
    ],
    "post_title": "CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes)",
    "prominence": "aside",
    "source_url": "https://www.reddit.com/r/netsec/comments/1wkeh8n/cve202677179_dockers_hypervisor_for_mac/",
    "entity_role": "vendor",
    "post_author": "natcoba",
    "upvote_ratio": 0.9320987654320988,
    "mention_count": 6,
    "mention_surge": true,
    "subreddit_url": "https://www.reddit.com/r/netsec/",
    "total_upvotes": 140,
    "comments_total": 13,
    "total_comments": 13,
    "other_companies": [
      {
        "name": "OrbStack",
        "role": "switching_to",
        "domain": "orbstack.dev"
      }
    ],
    "post_author_url": "https://www.reddit.com/user/natcoba/",
    "signal_category": "feedback",
    "comments_included": 4,
    "products_mentioned": [
      "Docker Desktop"
    ]
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.